Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Fedora 39 Update: mingw-python-jinja2 3.1.3 Critical HTML Injection Fix

fedora
Calendar Grey January 23, 2024
Dist Fedora Esm H88
Fedora upgrades mingw-python-jinja2 to version 3.1.3, addressing an HTML injection flaw documented in CVE-2024-22195.
Update to jinja2-3.1.3, fixes CVE-2024-22195.

Summary

MinGW Windows Python Jinja2 library.

Update Information:

Update to jinja2-3.1.3, fixes CVE-2024-22195.

Change Log

* Sun Jan 14 2024 Sandro Mani - 3.1.3-1 - Update to 3.1.3

References


[ 1 ] Bug #2257865 - CVE-2024-22195 mingw-python-jinja2: jinja2: HTML attribute injection when passing user input as keys to xmlattr filter [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2257865

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-ab372beea4' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html

Severity
critical
Lowest
Low
Medium
High
Critical

Name: mingw-python-jinja2
Product: Fedora 39
Version: 3.1.3
Release: 1.fc39
Summary: MinGW Windows Python Jinja2 library

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here